← Google Trust Services LLC cases
Bugzilla #1931413 Incident

Google Trust Services: New hire onboarding deviation from written procedure

RESOLVED FIXED Google Trust Services LLC
This summary was auto-generated by AI and revised by me when needed — accuracy improves with each update. Always refer to the official Bugzilla thread as the authoritative source. If you spot an inaccuracy, let me know via the contact form.
AI Summary

Google Trust Services (GTS) reported that, during a new hire onboarding process, some access control group memberships were granted in a different order than their documented procedures specify. GTS stated this resulted from multiple process deviations, including that access control group membership and the access ticket were handled after training but before the examination was completed, and that a team manager approved an access ticket type that should have been approved by the Policy Authority (PA). GTS said there was no impact to certificate issuance or validation, and that controls prevented premature access to CA systems because access required both access control group grants and a configuration deployment, with access gated by Multi-Party Authorization (MPA). GTS investigated and prepared an incident report, then implemented remediation changes to improve sequencing and reduce manual steps, including revising the process so the exam proctor files post-exam access requests, re-evaluating and reducing steps/approvals/systems, and simplifying onboarding sequencing. GTS later reported that automation for access group membership management was tested and is active, and that training process improvements were completed. The bug was resolved as FIXED, with GTS stating all action items were completed and requesting closure.

Model: gpt-5.4-nano Generated: 2026-06-13 21:36 UTC Revised: 2026-06-16 18:50 UTC Confidence: 0.90 8 comments
Chronology
  1. GTS identified an onboarding process deviation during new hire access provisioning and opened an incident report in the CA Program bug tracker.
  2. GTS published the incident report describing the deviations, impact assessment, and planned remediation.
  3. GTS reported completion of one scheduled action item by revising the access request process so the exam proctor files post-exam access requests.
  4. GTS reported completion of remaining action items, including access automation and training process improvements, and requested bug closure.
Thread Activity
  1. Google representative — GTS reported that new hire access group membership was granted in a different order than procedures specify, and said it would prepare an incident report and publish it by 2024-11-22.
  2. Google representative — GTS posted the incident report, stating training was complete but the examination was not completed before access control group membership and related approvals occurred, and described the current process, deviations, impact (no certificate issuance/validation impact), and investigation findings.
  3. Google representative — GTS requested setting the "Next update" field to 2024-12-06 for the next AI update.
  4. Google representative — GTS reported it revised the access request procedure so the exam proctor files post-exam access requests, and said additional improvements were continuing with further updates planned.
  5. Google representative — GTS reported completion of remaining action items, including reducing manual steps, testing and activating automation for access group membership, and improving the training process, and requested closure if no further comments.
  6. Mozilla representative — Mozilla requested a brief closing summary including incident description, root causes, remediation, any commitments, and confirmation that all action items were completed.
  7. Google representative — GTS provided the requested closure summary, stating the root cause was onboarding complexity and sequencing with insufficient controls to enforce the documented procedure, and that three remediation changes were implemented with no additional ongoing commitments beyond completed action items.
  8. Google representative — GTS requested the bug be closed if there were no further questions or comments.
Participants
Google representative Mozilla representative
External References
Similar Local Cases
#1948368 RESOLVED Incident Opened 2025-02-14 · Closed 2025-03-14 · 95% similar
Google Trust Services: Self-audit tooling MPIC perspective verification inconsistency
#1731164 RESOLVED Incident Opened 2021-09-16 · Closed 2023-02-22 · 88% similar
Google Trust Services: CRL validity period set to expected value plus one second
#1708516 RESOLVED Incident Opened 2021-04-29 · Closed 2023-02-22 · 87% similar
Google Trust Services: Failure to provide regular and timely incident updates
#1959867 RESOLVED Incident Opened 2025-04-11 · Closed 2025-06-10 · 87% similar
Google Trust Services: Inconsistent MPCAA secondary perspective logging
#1758372 RESOLVED Incident Opened 2022-03-07 · Closed 2023-02-22 · 86% similar
Google Trust Services: Incorrect OCSP response for issued certificate
#1522975 RESOLVED Ca Security Vulnerability Incident Opened 2019-01-25 · Closed 2023-02-22 · 79% similar
Google Trust Services: Improper OCSP response for intermediate certificate
#1902310 RESOLVED Incident Opened 2024-06-13 · Closed 2024-07-11 · 69% similar
Sectigo: Trusted Role Access provided prior to completion of onboarding process
#1866448 RESOLVED Certificate Misissuance Incident Opened 2023-11-24 · Closed 2024-02-14 · 69% similar
NAVER Cloud Trust Services: DV Certificate issued with improperly validated

We use only essential cookies and local browser storage for preferences and security. See our Privacy Policy for details.

Confirm action